Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfgv-4xh4-mff6

Опубликовано: 20 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.

EPSS

Процентиль: 38%
0.00167
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 3 года назад

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.

CVSS3: 5.6
nvd
почти 3 года назад

Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.

CVSS3: 5.6
debian
почти 3 года назад

Expired sessions were not securely terminated in the RestAPI for Tribe ...

EPSS

Процентиль: 38%
0.00167
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-613